CVE-2026-8643Medium· 5.5▾ Sunlitpip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
pip < 26.1.2Upgrade past the affected range:
pip 26.1.2Affected packages:
pip < 26.1.2Patched in:
pip 26.1.2Source: https://osv.dev/vulnerability/GHSA-wf93-45jw-7689
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-5752Medium· 5.5Command Injection in pip when used with Mercurial
CVE-2026-13346Medium· 6.5pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk e…
CVE-2026-3219Mediumpip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
CVE-2026-1703Lowpip Path Traversal vulnerability
CVE-2025-8869Mediumpip's fallback tar extraction doesn't check symbolic links point to extraction directory
CVE-2026-12243High· 7.5nltk: NLTK: Information disclosure via path traversal vulnerability (CVE-2026-12243)